EIP-7702's First Adversarial Case: $3.55M in Dormant Bridge Funds Exits in Two Transactions

CryptoWoo • • Research

At 06:14 UTC, a single external account on Ethereum executed two transactions back to back. The first swept $1.33 million. The second swept $2.22 million. Combined, roughly $3.55 million in cross-chain funds that had sat unclaimed inside a bridge contract for an extended period. The address of record, 0x4943, signed nothing at the moment of execution. The transaction type was 0x04, EIP-7702 delegated execution, submitted by address 0x24a9, an address that had previously received funds from Tornado Cash. No exploit contract. No flash loan. No reentrancy loop. A delegation, a batch, an exit.

That is the anomaly worth auditing. The mechanism used to move the money is not a bug. It is a feature that shipped with Ethereum's Pectra upgrade. It performed exactly as specified.

The ledger doesn't lie. It also doesn't flinch.

I spent 2017 rejecting 60% of ICO whitepapers for emission schedules that could not survive a spreadsheet. The lesson from that year is unchanged: code records intent, but code cannot record consent. What follows is an attempt to separate the two.

Context: what EIP-7702 actually does

EIP-7702 arrived with Pectra as a new transaction type, 0x04, that allows an externally owned account (EOA) to temporarily delegate its execution rights to a smart contract. In plain terms, an EOA can, for a defined window, borrow the logic of a contract and run it under its own address. This is account abstraction in its most pragmatic form. It lets a plain key-holder batch calls, sponsor gas, and compose multi-step operations without migrating to a smart-contract wallet.

The design is neutral. A delegated EOA can pay three vendors in one signature. It can also drain three token balances in one transaction. The same primitive supports efficiency and extraction.

The second concept here is unclaimed cross-chain funds. When a user bridges assets, the destination leg can stall: insufficient gas on the target chain, a failed contract interaction, or a user who simply lost control of the receiving address. The funds sit in the bridge, still owned on paper by the original address, but requiring specific conditions to extract. They are not lost. They are dormant.

Phalcon, the on-chain monitoring arm of BlockSec, disclosed the movement. A researcher operating as stuckfunds.eth had spent weeks repeatedly notifying 0x4943 on-chain that claimable funds were waiting. That notification history is now part of the record, and it matters more than it looks.

Context matters here too. We are writing in a bear market, and bear markets change what a security event means. In 2022 I ran a live monitoring protocol on stablecoin reserves, tracking mint and burn events across Ethereum and Tron in real time to catch de-peg risk. The lesson carried over: during drawdowns, capital is not looking for yield, it is looking for exits. A $3.55 million hole in a bridge contract is not a systemic event. But the mechanism behind it is, because it touches every EOA that has ever delegated execution rights. Survival questions outrank gain questions, and this is a survival question about account architecture.

Core: the evidence chain

Three facts anchor this case, and each carries a different weight.

Fact one, the mechanism. The claiming address 0x24a9 executed via EIP-7702 delegation. This explains the batching. Two transfers of $1.33M and $2.22M were processed in sequence under delegated logic, not as two manual key signatures. Delegation is what lets a single transaction empty a wallet's worth of assets in one motion. The defensive window collapses to block time.

Fact two, the mixer link. 0x24a9 had previously received funds from Tornado Cash. This is the loudest signal and the weakest evidence. Mixer interaction correlates strongly with an attempt to sever on-chain provenance, but it is not proof of wrongdoing. The same rail serves a privacy-conscious holder. The word previously matters: the exposure predates the claim, consistent with a pre-mix, execute, re-mix laundering pattern, or with an owner who simply values privacy. Both readings fit the data.

Fact three, the authorization. On-chain data confirms the delegation was cryptographically valid. That is the entire problem. A valid signature proves the mathematics worked. It does not prove the signer understood what they authorized, or that they authorized it at all. Validity and voluntariness are separate questions, and the ledger only answers the first.

The ledger has no hands. It records; it does not adjudicate.

Here is where I run the same checklist I use on any custody event, and where the audit stalls. Three mutually exclusive explanations exist, and the public record cannot separate them:

  • Voluntary signature. The owner delegated deliberately and moved their own funds.
  • Induced signature. A phishing prompt, a spoofed interface, or a social-engineering script captured a delegation the owner believed was something else.
  • Key compromise. The private key leaked, and the attacker delegated on the owner's behalf.

Each produces an identical on-chain footprint. The EOA delegated. The funds moved. The hash is the same in all three worlds.

That equivalence is the finding. Under the EOA model, one authorization equals total exposure. No second factor. No multisig quorum. No social-recovery backstop. EIP-7702 did not create this fragility, but it compressed the response window from hours of manual movement to a single delegated transaction executed at machine speed. A sweeper that had pre-scouted 0x4943's asset structure could clear two large balances in one call. That reconnaissance is not trivial, which is itself evidence: someone knew what sat in the account.

There is an ecosystem dimension the single-event framing hides. EIP-7702 is live, but the practices around it are not. Wallets do not yet render delegation scopes in a way a normal user can read. Revocation is technically possible and practically obscure. User education trails the feature by a wide margin. That gap, between a shipped capability and an unshipped defense, is where events like this live. The tool shipped. The guardrails did not.

Trace the transmission. For wallet and account-abstraction teams, this is a double-edged event: near-term reputational friction, long-term demand for smart-contract wallets, multisig, and social recovery as EOA replacements. For security firms, it is a clear tailwind, since on-chain monitoring and forensic response are exactly what the moment rewards. For cross-chain bridges, it is a quiet warning that dormant-fund reclaim flows need better tooling. For privacy rails, it is one more data point in a public argument that never resolves.

Contrarian: correlation is not conviction

The instinct is to read Tornado Cash and conclude theft. Resist it. Mixer adjacency is a provenance signal, not a verdict. If I ran this through the wash-trading filter I built in 2021, the one that analyzed wallet connectivity across 10,000 addresses to strip self-washed NFT sales, I would flag the mixer link as high-salience and low-conclusiveness. Salient because it dominates the narrative. Inconclusive because it cannot distinguish the attacker from the privacy holder.

EIP-7702's First Adversarial Case: $3.55M in Dormant Bridge Funds Exits in Two Transactions

There is a sharper point, and it is uncomfortable. The rescue notifications may have been the trigger. stuckfunds.eth repeatedly and publicly told 0x4943 that a large, claimable balance was waiting. That is a well-intentioned act. It is also a public advertisement that a specific address holds unclaimed value and may be inactive. If the claim was unauthorized, the notification history and the claim share a timeline. Correlation again, not causation. But the pattern deserves an audit: a dormant, high-value, publicly flagged address is a target profile. Public rescue can double as target selection.

The third blind spot is the label itself. Owner versus attacker for 0x4943 and 0x24a9 is an assumption the data does not yet support. We are assigning roles before the forensics are in.

What to watch next

The next signal is not the price of anything. It is whether 0x24a9 moves the funds again, and through which rail. A second mixer pass would sharpen the attribution considerably. Watch for 7702 authorization-revocation tooling from wallet vendors; its absence is the real risk. And watch stuckfunds.eth's future notices. If rescue channels quietly shift to private delivery, the industry will have admitted the paradox above without saying so.

One more audit note. The disclosed figure, $3.55 million, is small enough to be ignored by the market and large enough to matter to one address. That asymmetry is why the case is instructive. The dollar amount is trivial. The precedent is not.

The ledger doesn't lie. It just never tells you who was holding the pen.